Back to bug 2089301

Who When What Removed Added
Ying Cui 2022-05-23 11:54:07 UTC Severity unspecified high
CC ycui
Fabian Deutsch 2022-05-23 12:33:46 UTC Priority unspecified urgent
CC fdeutsch
Jed Lejosne 2022-05-23 15:09:49 UTC Assignee sgott jlejosne
Flags needinfo?(vsibirsk)
Jed Lejosne 2022-05-23 19:23:15 UTC Flags needinfo?(vsibirsk)
Martin Tessun 2022-05-24 08:21:57 UTC Flags needinfo?(jlejosne)
CC jlejosne, mtessun
Jed Lejosne 2022-05-24 15:35:16 UTC Flags needinfo?(jlejosne)
Qinghua Cheng 2022-05-25 11:58:52 UTC Depends On 2090219
Kedar Bidarkar 2022-05-25 12:03:00 UTC Target Release --- 4.11.0
Marc-Andre Lureau 2022-05-29 07:55:39 UTC Priority urgent high
CC sgott
Keywords TestOnly
Target Release 4.11.0 4.12.0
CC marcandre.lureau
Qianqian Zhu 2022-05-31 09:26:55 UTC CC qizhu
Kedar Bidarkar 2022-06-02 14:32:50 UTC Doc Type If docs needed, set a value Known Issue
Doc Text Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: VMs with an attached TPM device running in FIPS mode will not boot. For example
Doc Text , the default Windows 11 template includes a FIPS device because Windows 11 requires this by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS mode.
Doc Text Windows 11 works on other clusters.
Doc Text Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: VMs with an attached TPM device running in FIPS mode will not boot. For example, the default Windows 11 template includes a FIPS device because Windows 11 requires this by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS mode. Windows 11 works on other clusters.
Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: VMs with an attached TPM device running in FIPS mode will not boot. For example, the default Windows 11 template includes a TPM device because Windows 11 requires this by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS mode. Windows 11 works on other clusters.
Qinghua Cheng 2022-06-17 02:06:25 UTC Doc Text Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: VMs with an attached TPM device running in FIPS mode will not boot. For example
Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: Attempting to attach a vTPM device to a VM on a cluster running in FIPS mode will silently fail. For example
Doc Text , the default Windows 11 template includes a TPM device because Windows 11 requires this by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS mode.
, the default Windows 11 template includes a vTPM device because Windows 11 requires a TPM device by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS
Doc Text Windows 11 works on other clusters. mode. Windows 11 boots properly on other clusters.
Summary Not able to install windows 11 OS with vTPM in spec Windows 11 can't run on clusters in FIPS mode
Depends On 2097939
Qinghua Cheng 2022-06-17 02:58:56 UTC Depends On 2097947
Marc-Andre Lureau 2022-06-27 15:54:15 UTC Flags needinfo?(marcandre.lureau)
Flags needinfo?(marcandre.lureau)
Marc-Andre Lureau 2022-06-28 12:44:57 UTC Flags needinfo?(marcandre.lureau)
Flags needinfo?(marcandre.lureau)
Antonio Cardace 2022-07-18 12:28:07 UTC Status NEW ASSIGNED
CC acardace
Avital Pinnick 2022-07-26 10:19:10 UTC Doc Text Cause: swtpm does not account for FIPS algorithms with respect to TPM.

Consequence: Attempting to attach a vTPM device to a VM on a cluster running in FIPS mode will silently fail. For example, the default Windows 11 template includes a vTPM device because Windows 11 requires a TPM device by default.

Workaround (if any):

Result: Attempting to run Windows 11 in FIPS mode is unsupported. This note only applies to clusters running in FIPS mode. Windows 11 boots properly on other clusters.
Windows 11 virtual machines do not boot on clusters running in link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html-single/security_hardening/index#con_federal-information-processing-standard-fips_assembly_installing-the-system-in-fips-mode[FIPS mode]. Windows 11 requires a TPM (trusted platform module) device by default. However, the `swtpm` (software TPM emulator) package is incompatible with FIPS.
CC apinnick
Kedar Bidarkar 2022-11-09 13:33:44 UTC Link ID Red Hat Issue Tracker CLOUDBLD-11261
Target Release 4.12.0 4.13.0
Red Hat One Jira (issues.redhat.com) 2022-11-09 13:48:39 UTC Link ID Red Hat Issue Tracker CNV-18526
Dominik Holler 2022-12-12 08:24:55 UTC CC dholler
Red Hat Bugzilla 2022-12-15 08:28:49 UTC CC cnv-qe-bugs
Jed Lejosne 2023-06-05 14:01:39 UTC Target Release 4.13.0 4.14.0
Status ASSIGNED ON_QA

Back to bug 2089301